Hackers have exploited a critical software vulnerability in Coldcard hardware wallets to drain more than 1,755 Bitcoins worth approximately $110 million from roughly 5,000 wallets in an ongoing attack. Coldcard devices, manufactured by Canada-based Coinkite Inc., are specialized hardware units designed to keep cryptocurrency offline in cold storage, isolated from internet connectivity. According to on-chain data mapped by Galaxy Research, the attack escalated rapidly over several days. Initial breaches reported on July 30 accounted for 594 Bitcoins worth about $38 million swept from 500 addresses. Losses expanded to $70 million across 1,082 Bitcoins by August 1, reached $89 million across 1,367 Bitcoins by August 2, and passed $110 million across 1,755 Bitcoins by Monday, August 3. Engineering teams from Block Inc. identified the root cause as a defect in how Coinkite implemented random-number generation during wallet creation. The vulnerability traces back to a March 2021 firmware release, version 4.0.1, affecting Mk3 devices through firmware version 5.0.3. Instead of using the hardware true random-number generator, affected firmware routed seed phrase creation through a software pseudorandom generator. The generator relied on predictable, deterministic inputs, including device serial numbers and internal clock states. This allowed external attackers to systematically recalculate potential master seed phrases offline and reconstruct private keys without ever gaining physical access to the devices. "It exposes the fallacy of your crypto being offline," said Aneirin Flynn, chief executive officer of cybersecurity firm Failsafe. "The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered." Victims reported that funds were swept automatically without any phishing interaction or physical compromise. Individual investor Jonathan Goodman stated that $1.6 million in Bitcoin wa
Prepared by Christopher Adams and reviewed by editorial team.
左:突显了不受监管的加密货币存储中的系统性监管失误和风险。 中:报告了有关固件缺陷和链上资金流动的技术事实。 右:强调了个人用户在自我保管模型中的责任和风险。
关于 2026 年 7 月 30 日固件漏洞和助记词生成风险的 Coinkite 安全公告。 指向原始触发源的直接 URL(如果可用,但仅限 1 个): https://blog.blockstream.com/jade-unaffected-coldcard-vulnerability/
No left-leaning sources found for this story.
Hackers Exploit Coldcard Flaw to Drain $110 Million in Bitcoin
Insurance Journal / Bloomberg Cointelegraph The Hacker News Blockstream Blog MyBroadband CyberInsider The Hacker News IG PYMNTS Bitcoin Well Infosecurity Magazine Medium (The Prediction Market Intelligence) The Straits Times CoinDesk Blockaid Security Blog Decrypt Bloomberg TRM Insights Galaxy ResearchNo right-leaning sources found for this story.
Comments